Fusion Prevent
← Resources

Threat landscape

43% of UK businesses were attacked last year. Here's what actually happened to them.

1 September 2026 · 2 min read · Fusion Prevent

Every year the Department for Science, Innovation and Technology publishes the Cyber Security Breaches Survey. Every year the number is bad, and every year most firms read the headline and move on. This year 43% of UK businesses reported an attempted or successful attack — more than 600,000 organisations.

The number worth sitting with is not 43%. It is the breakdown of how.

Phishing is still the front door

Phishing was the most common attack type, hitting 38% of businesses, and 69% of those affected called it the most disruptive incident of their year. Not ransomware. Not a zero-day. A convincing email.

The reason it works has changed. Two years ago a well-crafted, personalised phishing email took effort, which reserved it for targets worth the effort. AI has removed that constraint. The ICO issued an advisory on AI-powered threats in May 2026 for exactly this reason: being small and unremarkable has stopped being a defence, because personalisation is now free.

The attack usually starts with a password that already leaked

Here is the part that surprises the managing partners we speak to. In most successful account compromises, nobody guessed anything. The password was already sitting in a breach dump from a service the employee signed up to years ago — a webinar platform, a recruitment site, a supplier portal — and it was reused.

Research from Proofpoint found that in 65% of successful account takeovers, the victim had two-factor authentication switched on. It didn't matter. A single phishing email or a SIM swap got the attacker past it, because the password itself was already known.

What it costs

The survey puts the average cost of an attack at £195,000. For a firm holding client funds and confidential matters, that figure is low. The real cost is the week — sometimes the month — without access to systems, the clients who leave when their data turns up on a leak site, and the regulatory conversation that follows.

Ask yourself what your daily revenue is. Multiply it by a week. Then by a month. That is the number to hold in mind, and it is why "we've never had a breach" is the wrong reassurance. It says nothing about the credentials already circulating.

The question worth asking

Not "are we protected?" — every firm has a firewall and backups. The question is: who is looking at our firm from the outside, the way an attacker would, and telling us what they can see?

For most firms under 250 people the honest answer is nobody. That is the gap.

See it for your own firm

Run the free 60-second exposure scan.

The same outside-in view an attacker starts from. Public data only — nothing is probed.

Run the free scan